---
id: CVE-2025-6558
title: >-
  Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome
  prior to 138.0.7204.157 allowed a remote attacker to potentially perform a
  sandbox escape via a crafted HTML page
summary: >-
  Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome
  prior to 138.0.7204.157 allowed a remote attacker to potentially perform a
  sandbox escape via a crafted HTML page. (Chromium security severity: High)
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: google
product: chrome
affected:
  - chrome < 138.0.7204.157
  - debian_linux = 11.0
  - safari < 18.6
  - ipados < 18.6
  - iphone_os < 18.6
  - macos < 15.6
  - visionos < 2.6
  - watchos < 11.6
  - wpe_webkit < 2.48.0
  - webkitgtk < 2.48.0
patched:
  - chrome 138.0.7204.157
  - safari 18.6
  - ipados 18.6
  - iphone_os 18.6
  - macos 15.6
  - visionos 2.6
  - watchos 11.6
  - wpe_webkit 2.48.0
  - webkitgtk 2.48.0
published: '2025-07-15'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T13:10:00.320'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-6558'
references:
  - url: >-
      https://chromereleases.googleblog.com/2025/07/stable-channel-update-for-desktop_15.html
    label: chrome-cve-admin@google.com
  - url: 'https://issues.chromium.org/issues/427162086'
    label: chrome-cve-admin@google.com
  - url: 'http://seclists.org/fulldisclosure/2025/Aug/0'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/30'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/32'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/35'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://seclists.org/fulldisclosure/2025/Jul/37'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.openwall.com/lists/oss-security/2025/08/02/1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2025/08/msg00015.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-6558
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
  - cve.org
epss: 0.09585
epssPercentile: 0.95257
kev: true
kevDateAdded: '2025-07-22'
kevDueDate: '2025-08-12'
kevRansomware: false
exploited: true
exploits:
  github: 2
  githubRepos:
    - 'https://github.com/gmh5225/CVE-2025-6558-exp'
    - 'https://github.com/DevBuiHieu/CVE-2025-6558-Proof-Of-Concept'
  checkedAt: '2026-09-24T13:43:59.532Z'
exploitAvailable: true
ssvc:
  exploitation: active
  automatable: 'no'
  technicalImpact: total
  timestamp: '2025-07-22T03:55:29.491017Z'
ingestedAt: '2026-09-21T17:49:53.184Z'
---

## Overview

Insufficient validation of untrusted input in ANGLE and GPU in Google Chrome prior to 138.0.7204.157 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

## Affected

- `chrome < 138.0.7204.157`
- `debian_linux = 11.0`
- `safari < 18.6`
- `ipados < 18.6`
- `iphone_os < 18.6`
- `macos < 15.6`
- `visionos < 2.6`
- `watchos < 11.6`
- `wpe_webkit < 2.48.0`
- `webkitgtk < 2.48.0`

## Remediation

Upgrade past the affected range:

- `chrome 138.0.7204.157`
- `safari 18.6`
- `ipados 18.6`
- `iphone_os 18.6`
- `macos 15.6`
- `visionos 2.6`
- `watchos 11.6`
- `wpe_webkit 2.48.0`
- `webkitgtk 2.48.0`
